Critical Slack Vulnerability Let Attackers Steal Data From Private Slack Channels

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered vulnerability in Slack AI could allow attackers to exfiltrate sensitive data from private Slack channels. Cybersecurity researchers responsibly disclosed a vulnerability to Slack that involves manipulating the language model used for content generation. This vulnerability allows attackers …

Dell SupportAssist Vulnerability Exposes PCs to Privilege Escalation Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been identified in Dell’s SupportAssist for Home PCs, specifically affecting the installer executable version 4.0.3. This flaw, tracked as CVE-2024-38305, allows local low-privileged authenticated attackers to escalate their privileges, potentially leading to the execution of …

Critical Vulnerability In OpenBMCs For Servers, Leads To Full Compromise

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

BMCs are specialized microcontrollers embedded in servers and other devices, responsible for monitoring and managing hardware health, including temperature, voltage, and system logs. Cybersecurity researchers at Tetrel Sec recently discovered a critical vulnerability in the slpd-lite sub-component of the OpenBMC …

Hackers Exploit PHP Vulnerability in Windows To Execute Arbitrary Code Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers at Symantec recently identified a new malware that exploits a PHP vulnerability(CVE-2024-4577) in the CGI argument injection flaw. This vulnerability affects all versions of PHP installed on the Windows operating system and eventually executes arbitrary code remotely. A …

Hackers Exploited AWS ENV Files to Attack 110,000 Domains & Steal Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated extortion campaign targeted 110,000 domains by exploiting exposed .env files on unsecured web applications. The attackers obtained AWS IAM access keys from these files, which allowed them to create new IAM roles and policies with unlimited access.  This …

Microsoft Launches Unified Teams App for Personal & Work Environments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has unveiled a significant update to its popular collaboration platform, Microsoft Teams, by launching a unified app that brings together personal, work, and education accounts in a single interface. This new unified Teams app is now available on Windows …

Atlassian Bamboo Data Center & Server Flaw Let Attackers Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Atlassian has issued a security advisory for a newly discovered high-severity vulnerability affecting its Bamboo Data Center and Server products. The vulnerability, identified as CVE-2024-21689, has a CVSS score of 7.6, indicating a high severity level. This flaw allows attackers to …

New UULoader Attacking Users Via Weaponized PDF Documents

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Malicious .msi installers disguised as legitimate software actively target Korean and Chinese speakers by dubbing UULoader, contain a loader likely developed by a Chinese speaker, and evade detection by most security solutions.  The malware employs DLL side-loading to execute obfuscated …

Outlook Zero-click RCE Vulnerability Technical Details Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers at Morphisec have uncovered critical technical details about the recently discovered zero-click remote code execution (RCE) vulnerability in Microsoft Outlook, identified as CVE-2024-38021. This vulnerability poses a significant security risk, allowing potential attackers to execute arbitrary code without user …

10 Best Cloud VPN Providers – 2024

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A cloud VPN (Virtual Private Network) provider is a company that offers VPN services through cloud technology. This can save time and resources and reduce the risk of security breaches.  These services allow users to connect to the internet securely …